<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Vulnerabilities &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Sat, 20 Jun 2026 03:24:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>Vulnerabilities &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cloud Infrastructure Resilience: Mitigating Advanced Layer 7 Vulnerabilities and Securing High-Throughput Database Handshakes</title>
		<link>https://en.anonyviet.com/cloud-infrastructure-resilience-mitigating-advanced-layer-7-vulnerabilities-and-securing-high-throughput-database-handshakes/</link>
					<comments>https://en.anonyviet.com/cloud-infrastructure-resilience-mitigating-advanced-layer-7-vulnerabilities-and-securing-high-throughput-database-handshakes/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sat, 20 Jun 2026 03:24:22 +0000</pubDate>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Advanced]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Handshakes]]></category>
		<category><![CDATA[HighThroughput]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[Layer]]></category>
		<category><![CDATA[Mitigating]]></category>
		<category><![CDATA[Resilience]]></category>
		<category><![CDATA[Securing]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=22114</guid>

					<description><![CDATA[The global cybersecurity landscape and the architecture of enterprise cloud networks throughout 2026 are facing an unprecedented surge in sophisticated, automated exploits. Modern system administrators and security engineers can no longer rely on traditional stateful firewalls or static IP-blocking policies to shield critical infrastructure nodes. Today, malicious actors deploy highly coordinated, multi-vector Application Layer (Layer [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p>The global cybersecurity landscape and the architecture of enterprise cloud networks throughout 2026 are facing an unprecedented surge in sophisticated, automated exploits. Modern system administrators and security engineers can no longer rely on traditional stateful firewalls or static IP-blocking policies to shield critical infrastructure nodes. Today, malicious actors deploy highly coordinated, multi-vector Application Layer (Layer 7) DDoS attacks that precisely mimic legitimate user interactions to exhaust server CPU cycles and database connection pools. In this intensely hostile digital environment, engineering a <strong>coordinated pressure strategy</strong> against network edge latency, deploying continuous zero-trust authentication matrices, and verifying micro-service isolation protocols have become the absolute core requirements for mitigating operational downtime, avoiding catastrophic data breaches, and maintaining high availability across international distribution nodes.</p>
<div class="av-telegram-box" style="margin:16px 0;">
<div style="border:1px solid #dbeafe; background:linear-gradient(135deg,#eff6ff 0%,#ecfeff 100%); border-radius:14px; padding:14px 16px; box-shadow:0 4px 14px rgba(0,0,0,.06); text-align:center;">
<p> <span style="display:inline-block; margin-right:4px;">📢</span> Tham gia kênh <span style="color:#2563eb;">Telegram</span> của <span style="color:#0f766e;">AnonyViet</span></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" target="_blank" rel="noopener nofollow" style="display:inline-flex; align-items:center; justify-content:center; gap:8px; background:#229ED9; color:#fff; text-decoration:none; font-weight:700; font-size:14px; padding:10px 14px; border-radius:10px; box-shadow:0 4px 10px rgba(34,158,217,.25);"><br />
<span>👉 Vào Telegram AnonyViet</span><br />
</a></p>
<p> Cập nhật bài mới, tools hay và thủ thuật IT nhanh nhất</p>
</div>
</div>
<p>This fundamental shift toward active, behavioral threat mitigation requires infrastructure analysts to parse immense volumes of real-time server telemetry. When supervising global web architectures under active stress, the technical capability to separate malicious high-frequency script inquiries from authentic user traffic spikes remains a mandatory asset for long-term platform survival and system validation.</p>
<p><img post-id="22114" fifu-featured="1" decoding="async" class="aligncenter" src="https://anonyviet.com/wp-content/uploads/2026/06/word-image-101403-1.jpg" alt="Cloud Infrastructure Resilience: Mitigating Advanced Layer 7 Vulnerabilities and Securing High-Throughput Database Handshakes" title="Cloud Infrastructure Resilience: Mitigating Advanced Layer 7 Vulnerabilities and Securing High-Throughput Database Handshakes" title="Cloud Infrastructure Resilience: Mitigating Advanced Layer 7 Vulnerabilities and Securing High-Throughput Database Handshakes 5"/></p>
<h2 id="ftoc-1-quantitative-performance-under-stress-cryptographic-handshakes-and-packet-analysis" class="ftwp-heading"><strong>1. Quantitative Performance Under Stress: Cryptographic Handshakes and Packet Analysis</strong></h2>
<p>Maintaining an unbreachable defense perimeter while processing continuous transactional traffic requires deep, non-stop inspection of active protocol states. High-performance security appliances do not simply monitor basic bandwidth usage; they evaluate individual transport-layer handshakes and asymmetric cryptographic verification speeds to detect anomalous structural patterns before they reach the central database layer.</p>
<p>To measure the defensive integrity of a high-load network infrastructure, security operation centers monitor three critical parameters:</p>
<ul>
<li><strong>Asymmetric Handshake Congestion Index:</strong> The exact time delta required for edge servers to process and validate TLS 1.3 cryptographic handshakes under sudden load spikes.</li>
<li><strong>Malicious Payload Interception Rate:</strong> The real-time efficiency of deep packet inspection (DPI) algorithms in identifying hidden SQL injection patterns within encrypted streams.</li>
<li><strong>Socket Exhaustion Recovery Velocity:</strong> The speed with which the operating system kernel recycles abandoned or malicious TCP connections to prevent system-wide buffer starvation.</li>
</ul>
<h2 id="ftoc-2-preventive-network-edge-hardening-3-pillars-of-infrastructure-defense" class="ftwp-heading"><strong>2. Preventive Network Edge Hardening: 3 Pillars of Infrastructure Defense</strong></h2>
<p>Building a highly resilient, enterprise-level digital architecture depends on the synchronized execution of three distinct cybersecurity disciplines:</p>
<ul>
<li><strong>De-monolithization of Authentication Gateways:</strong> Separating primary application logic from user-validation microservices to ensure an isolated attack cannot compromise core system nodes.</li>
<li><strong>Dynamic Content Delivery Filtering:</strong> Deploying intelligent Web Application Firewalls (WAF) directly at the regional edge node level to drop anomalous traffic before it enters private cloud pathways.</li>
<li><strong>Automated Rate-Limiting Matrices:</strong> Implementing real-time, behavior-based connection limits that throttle suspicious IP blocks without impacting valid consumer interactions.</li>
</ul>
<h2 id="ftoc-3-strategic-telemetry-processing-the-practicality-of-critical-filtering-habits" class="ftwp-heading"><strong>3. Strategic Telemetry Processing: The Practicality of Critical Filtering Habits</strong></h2>
<p>In large-scale security operations monitoring, a continuous, unmanaged deluge of firewall alerts, automated system pings, and access log notifications can quickly overwhelm technical response teams. Developing sharp, consistent <strong>critical-filtering habits</strong> enables cybersecurity directors to bypass thousands of low-severity notifications and instantly isolate high-priority infrastructure anomalies, such as sudden privilege-escalation attempts within the database backend or unexpected bursts of outbound traffic that point to potential data exfiltration vectors.</p>
<p>Experienced network engineers strictly avoid unstructured terminal log displays. Instead, they implement unified security dashboards that organize system telemetry cleanly and structurally, ensuring that primary tactical defense choices proceed without visual or cognitive interference.</p>
<h2 id="ftoc-4-advanced-server-environments-and-high-speed-real-time-analytical-synchronization" class="ftwp-heading"><strong>4. Advanced Server Environments and High-Speed Real-Time Analytical Synchronization</strong></h2>
<p>Supervising immense live transactional volumes and high-speed data synchronization on a global scale demands robust cloud setups capable of processing millions of independent data updates without connection degradation. Digital networks built to handle rapid, fluid data forecasting require specialized backend servers that eliminate processing latency and possess native protection against packet corruption, giving global users instant, seamless access to shifting metric columns.</p>
<p>A prime illustration of this technical resilience in processing heavy real-time data feeds under high security standards can be found within the digital environments that track highly fluid international statistics. Utilizing server setups specifically engineered to prevent packet lag and mitigate automated scanning scripts during massive global events, the digital infrastructure behind <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fkr.parimatch.com%2F" rel="noopener" class="local-link">파리매치</a> structures and handles extensive information indices with absolute automated precision. Its web layout relies on a clean, dark-themed user interface that organizes multiple columns of shifting metrics, allowing analytical minds to monitor dynamic global event distributions without visual clutter, interface delays, or security vulnerabilities. This technological fluidness provides a fast, responsive, and completely protected environment for managing complex live analytical indices worldwide.</p>
<h2 id="ftoc-conclusion-new-horizons-for-enterprise-cybersecurity-networks" class="ftwp-heading"><strong>Conclusion: New Horizons for Enterprise Cybersecurity Networks</strong></h2>
<p>The current state of global network infrastructure in 2026 highlights that the sustainability of modern enterprise platforms depends heavily on algorithmic precision, low-level optimization, and proactive data management. Applying a <strong>coordinated pressure strategy</strong> against operational network friction, verifying cryptographic protocols across distributed supply networks, and maintaining focused <strong>critical filtering habits</strong> are mandatory tasks for today’s industry leaders. Observing how elite international digital networks architect and shield their high-speed data streams offers an invaluable technical blueprint for commercial developers, ensuring that next-generation software management applications remain structurally balanced, fast, and completely safe from external disruption.</p>
<p> </p>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/cloud-infrastructure-resilience-mitigating-advanced-layer-7-vulnerabilities-and-securing-high-throughput-database-handshakes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2026/06/word-image-101403-1.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>North Korean hackers take advantage of Windows vulnerabilities to attack with Rootkits</title>
		<link>https://en.anonyviet.com/north-korean-hackers-take-advantage-of-windows-vulnerabilities-to-attack-with-rootkits/</link>
					<comments>https://en.anonyviet.com/north-korean-hackers-take-advantage-of-windows-vulnerabilities-to-attack-with-rootkits/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sat, 02 Mar 2024 09:25:40 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[advantage]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Korean]]></category>
		<category><![CDATA[North]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=14825</guid>

					<description><![CDATA[The notorious hacker group Lazarus from North Korea exploited a &#8220;zero-day&#8221; security vulnerability in the Windows operating system to escalate privileges to mistakenly attack users. This is part of their attack campaign using a rootkit called FudModule. This vulnerability, codenamed CVE-2024-21338, discovered by Avast during Lazarus attacks last year. The company created a test exploit [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="markdown markdown-main-panel ui-v2-enabled" dir="ltr">
<p data-sourcepos="5:1-5:273">The notorious hacker group Lazarus from North Korea exploited a &#8220;zero-day&#8221; security vulnerability in the Windows operating system to escalate privileges to mistakenly attack users.  This is part of their attack campaign using a rootkit called <strong>FudModule</strong>.</p>
<p data-sourcepos="5:1-5:273"><img post-id="14825" fifu-featured="1" fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-56668" src="https://anonyviet.com/wp-content/uploads/2024/03/hacker-Lazarus-Lazarus-.jpg" alt="North Korean hackers take advantage of Windows vulnerabilities to attack with Rootkits" title="North Korean hackers take advantage of Windows vulnerabilities to attack with Rootkits" width="552" height="385" title="North Korean hackers take advantage of Windows vulnerabilities to attack with Rootkit 2" srcset="https://anonyviet.com/wp-content/uploads/2024/03/hacker-Lazarus-Lazarus-.jpg 552w, https://anonyviet.com/wp-content/uploads/2024/03/hacker-Lazarus-Lazarus--300x209.jpg 300w" /></p>
<p data-sourcepos="7:1-7:217">This vulnerability, codenamed <strong>CVE-2024-21338</strong>, discovered by Avast during Lazarus attacks last year.  The company created a test exploit (PoC) and submitted a report to Microsoft in August 2023.</p>
<p data-sourcepos="9:1-9:335">Microsoft patched the vulnerability during its “Patch Tuesday” security update in February 2024. However, the initial announcement of CVE-2024-21338 did not mention that it had been exploited In reality.  On Wednesday, the tech giant updated its notification to warn customers that the exploit was still ongoing.</p>
<p data-sourcepos="11:1-11:355">Avast&#39;s blog post on Wednesday provided a detailed technical description of the vulnerability and how Lazarus exploited this CVE to distribute the rootkit.  The location of the attack is located in the &#39;appid.sys&#39; driver related to Microsoft&#39;s AppLocker security feature.  Instead of installing malicious drivers themselves (BYOVD), Hackers will target a driver available in many systems to avoid detection.</p>
<p><span style="color: #008000"><em><strong>Rootkits</strong> is a type of malware (<strong>malware. malware</strong>) is designed to hide its or other malware&#39;s existence in the computer system.  Rootkits penetrate deeply into the system with high-level access (root or administrator), allowing hackers to control the entire system without being detected.  Rootkits can cause many security problems, including stealing personal information, monitoring user activity, and installing additional malware.  Due to their high level of concealment, rootkits are difficult to detect and remove.</em></span></p>
<p data-sourcepos="13:1-13:329">Avast explains: &#8220;By exploiting such vulnerabilities, Hackers minimize saving or downloading other malicious drivers.&#8221;  This helps Hackers attack the system kernel (kernel) so they can bypass most detection mechanisms and even work on systems that apply driver control.</p>
<p data-sourcepos="15:1-15:287">Through CVE-2024-21338, hacker Lazarus has elevated User rights on the compromised system and created a direct read/write mechanism at the operating system kernel level.  This trick allows them to directly manipulate kernel objects in the updated version of the FudModule rootkit (appearing in 2022).</p>
<p data-sourcepos="17:1-17:180">The new rootkit version has improvements that increase stealth and disable security software AhnLab V3 Endpoint Security, Windows Defender, CrowdStrike Falcon and HitmanPro.</p>
<p data-sourcepos="19:1-19:128">The Lazarus campaign tracked by Avast also used a remote access trojan (<a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F%3Fs%3Drat" rel="noopener">RAT</a>) new, detailed information will be announced by the company later.</p>
<p data-sourcepos="29:1-29:65">
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/north-korean-hackers-take-advantage-of-windows-vulnerabilities-to-attack-with-rootkits/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2024/03/hacker-Lazarus-Lazarus-.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to Find Vulnerable Vulnerabilities Using Google Dorks</title>
		<link>https://en.anonyviet.com/how-to-find-vulnerable-vulnerabilities-using-google-dorks/</link>
					<comments>https://en.anonyviet.com/how-to-find-vulnerable-vulnerabilities-using-google-dorks/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Fri, 25 Aug 2023 22:49:10 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Dorks]]></category>
		<category><![CDATA[Find]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerable]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=13039</guid>

					<description><![CDATA[Google&#8217;s advanced search operators are called Google Dorking. Why can hackers use this technique to find vulnerable vulnerabilities? In a word, this technique uses Google to search for exactly what you want using specific keywords or commands. Basically, it narrows down the search to find what you need. Join the channel Telegram belong to AnonyViet [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p>Google&#8217;s advanced search operators are called <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftag%2Fdork%2F" class="local-link" rel="noopener">Google Dorking</a>.  Why can hackers use this technique to find vulnerable vulnerabilities?  In a word, this technique uses Google to search for exactly what you want using specific keywords or commands.  Basically, it narrows down the search to find what you need. <img post-id="13039" fifu-featured="1" decoding="async" fetchpriority="high" class="aligncenter wp-image-41194 size-full" src="https://anonyviet.com/wp-content/uploads/2022/04/1_zA_nrmrKwrbQKOecCfUpkQ.jpeg" alt="How to Find Vulnerable Vulnerabilities Using Google Dorks" title="How to Find Vulnerable Vulnerabilities Using Google Dorks" width="825" height="390" srcset="https://anonyviet.com/wp-content/uploads/2022/04/1_zA_nrmrKwrbQKOecCfUpkQ.jpeg 825w, https://anonyviet.com/wp-content/uploads/2022/04/1_zA_nrmrKwrbQKOecCfUpkQ-300x142.jpeg 300w, https://anonyviet.com/wp-content/uploads/2022/04/1_zA_nrmrKwrbQKOecCfUpkQ-768x363.jpeg 768w, https://anonyviet.com/wp-content/uploads/2022/04/1_zA_nrmrKwrbQKOecCfUpkQ-750x355.jpeg 750w" sizes="(max-width: 825px) 100vw, 825px" title="How to Find Vulnerable Vulnerabilities Using Google Dorks 12"/></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> ???? <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  ????</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>Google Dorking uses some of the inherent capabilities of google to find exact things on the internet through specific search strings.  It can be log files, error files, webcams opened on the internet and even internal or admin pages that give us access to the device.  In some cases, you can also find the password in the error log file.  Sometimes even the administrative configuration files are exposed to the internet because the server is set up incorrectly.</p>
<p><img decoding="async" class="size-medium wp-image-41195 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/04/1_Y3XJ7jK5pwBKXAHj0SyEvQ-1-300x297.gif" alt="How to Find Vulnerable Vulnerabilities Using Google Dorks 8" width="300" height="297" srcset="https://anonyviet.com/wp-content/uploads/2022/04/1_Y3XJ7jK5pwBKXAHj0SyEvQ-1-300x297.gif 300w, https://anonyviet.com/wp-content/uploads/2022/04/1_Y3XJ7jK5pwBKXAHj0SyEvQ-1-150x150.gif 150w, https://anonyviet.com/wp-content/uploads/2022/04/1_Y3XJ7jK5pwBKXAHj0SyEvQ-1-75x75.gif 75w" sizes="(max-width: 300px) 100vw, 300px" title="How to Find Vulnerable Vulnerabilities Using Google Dorks 13"/></p>
<p>Google Dorking is done by Google search operators.  Some typical operators:</p>
<ul>
<li><strong class="kd jb">site:<keyword></strong> – used to limit search results to a specific site.  For example, google to find hack related blogs on the website https://gourav-dhar.com:<br /><code>hacking site:gourav-dhar.com</code></li>
<li><strong class="kd jb">inurl:<keyword> </strong>– is used to specify which keywords should be in the URL.  For the above query, if you want the URL to contain ethical, you can use:<br /><code>hacking site:gourav-dhar.com inurl:ethical</code></li>
</ul>
<p>You will get the following results:</p>
<p><img decoding="async" class="size-full wp-image-41202 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/04/1_89Xb2Yi5_oOyHZy848Ym5A.jpg" alt="How to Find Vulnerable Vulnerabilities Using Google Dorks 9" width="479" height="626" srcset="https://anonyviet.com/wp-content/uploads/2022/04/1_89Xb2Yi5_oOyHZy848Ym5A.jpg 479w, https://anonyviet.com/wp-content/uploads/2022/04/1_89Xb2Yi5_oOyHZy848Ym5A-230x300.jpg 230w" sizes="(max-width: 479px) 100vw, 479px" title="How to Find Vulnerable Vulnerabilities Using Google Dorks 14"/></p>
<ul>
<li><strong class="kd jb">intext:<keyword></strong> – This operator checks the parameters contained in the site&#8217;s metadata (i.e. the information you see on the title and description of a google search).</li>
<li><strong class="kd jb">intitle:<keyword></strong> – Results will only return pages that contain the keyword in the HTML title</li>
<li><strong class="kd jb">allintitle</strong> <strong class="kd jb">:<keyword></strong> – Search for all keywords specified in the title.</li>
<li><strong class="kd jb">allinurl</strong> <strong class="kd jb">:<keyword></strong> – Search all keywords in url.</li>
<li><strong class="kd jb">filetype:<keyword></strong> – Look for clear document types.  filetype:pdf will search for pdf files contained in web pages</li>
<li><strong class="kd jb">ext:<keyword></strong> – Same as filetype.  ext:pdf finds the pdf extension.</li>
<li><strong class="kd jb">cache</strong> <strong class="kd jb">:<keyword></strong> – Used to see the Google cached version of a web page</li>
</ul>
<p>And there are several other search operators that can also be found via Google Search.</p>
<h2 id="ftoc-cach-tim-lo-hong-de-bi-tan-cong-bang-google-dorks" class="ftwp-heading">How to Find Vulnerable Vulnerabilities Using Google Dorks</h2>
<h3 id="ftoc-1-kiem-tra-nhat-ky-de-tim-thong-tin-dang-nhap" class="ftwp-heading">1. Check the log for login information</h3>
<p><code>allintext:username filetype:log</code></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-41203 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/04/1_gDl2d8cszM2nbFXo1Q51HA.jpg" alt="How to Find Vulnerable Vulnerabilities Using Google Dorks 10" width="569" height="639" srcset="https://anonyviet.com/wp-content/uploads/2022/04/1_gDl2d8cszM2nbFXo1Q51HA.jpg 569w, https://anonyviet.com/wp-content/uploads/2022/04/1_gDl2d8cszM2nbFXo1Q51HA-267x300.jpg 267w" sizes="auto, (max-width: 569px) 100vw, 569px" title="How to Find Vulnerable Vulnerabilities Using Google Dorks 15"/></p>
<p>We will get a list of log files containing “username”.  This can be useful to hackers if the log contains user credentials.  If you explore the results a bit and apply filters, you should be able to find a username or password for further mining.</p>
<h3 id="ftoc-2-tim-cac-webcam-de-bi-truy-cap" class="ftwp-heading">2. Find vulnerable webcams</h3>
<p>Google <code>intitle:”webcamxp 5"</code> and you&#8217;ll find a list of webcams that you can access right away.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-41205 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/04/1_lbdWpUg3QO7kYQ9cULGesw.jpg" alt="How to Find Vulnerable Vulnerabilities Using Google Dorks 11" width="700" height="532" srcset="https://anonyviet.com/wp-content/uploads/2022/04/1_lbdWpUg3QO7kYQ9cULGesw.jpg 700w, https://anonyviet.com/wp-content/uploads/2022/04/1_lbdWpUg3QO7kYQ9cULGesw-300x228.jpg 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to Find Vulnerable Vulnerabilities Using Google Dorks 16"/></p>
<p>I can watch live webcams of some classes. <img decoding="async" loading="lazy" class="size-full wp-image-41206 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/04/1_YjaXlqmXdZvdudoM1qotBQ.jpg" alt="How to Find Vulnerable Vulnerabilities Using Google Dorks 12" width="409" height="406" srcset="https://anonyviet.com/wp-content/uploads/2022/04/1_YjaXlqmXdZvdudoM1qotBQ.jpg 409w, https://anonyviet.com/wp-content/uploads/2022/04/1_YjaXlqmXdZvdudoM1qotBQ-300x298.jpg 300w, https://anonyviet.com/wp-content/uploads/2022/04/1_YjaXlqmXdZvdudoM1qotBQ-150x150.jpg 150w, https://anonyviet.com/wp-content/uploads/2022/04/1_YjaXlqmXdZvdudoM1qotBQ-75x75.jpg 75w" sizes="auto, (max-width: 409px) 100vw, 409px" title="How to Find Vulnerable Vulnerabilities Using Google Dorks 17"/></p>
<p>The best place for you to start practicing is <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.exploit-db.com%2Fgoogle-hacking-database" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Google Hacking Database</a>.  If you are unsure about search operators, then you should check out this site.  Some people have searched before so you can use their search queries.  The Google Hacking Database or Exploit Database looks like the image below and you can enter your queries in the top right.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-41197 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/04/1_3Sw2QeNgh4glSlG26rZAag.jpg" alt="How to Find Vulnerable Vulnerabilities Using Google Dorks 13" width="700" height="261" srcset="https://anonyviet.com/wp-content/uploads/2022/04/1_3Sw2QeNgh4glSlG26rZAag.jpg 700w, https://anonyviet.com/wp-content/uploads/2022/04/1_3Sw2QeNgh4glSlG26rZAag-300x112.jpg 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to Find Vulnerable Vulnerabilities Using Google Dorks 18"/></p>
<h2 id="ftoc-tong-ket-ve-google-dorks" class="ftwp-heading">Summary of Google Dorks</h2>
<p>What I just did above is not illegal.  We are only looking for information that has already been made public.  Hackers use google dorks to find information that may have been accidentally made public.  However, it is up to the person to use this information.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;41191&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 0\/5 - (0 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;C\u00e1ch t\u00ecm l\u1ed7 h\u1ed5ng d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng b\u1eb1ng Google Dorks&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>
            <span class="kksr-muted">Rate this post</span>
    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-find-vulnerable-vulnerabilities-using-google-dorks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2022/04/1_zA_nrmrKwrbQKOecCfUpkQ.jpeg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to scan for system vulnerabilities with MITER ATTCK</title>
		<link>https://en.anonyviet.com/how-to-scan-for-system-vulnerabilities-with-miter-attck/</link>
					<comments>https://en.anonyviet.com/how-to-scan-for-system-vulnerabilities-with-miter-attck/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 02 Aug 2023 23:51:47 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ATTCK]]></category>
		<category><![CDATA[MITER]]></category>
		<category><![CDATA[Scan]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=12858</guid>

					<description><![CDATA[What is MITER ATTCK? Let&#8217;s find out in this article. As technology advances, we are more and more aware of the importance of network security. The danger of cybercrime also increases year by year. To deal with this, cybersecurity professionals are embarking on the development of new security tools to fight hackers every day. Among [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p>What is MITER ATTCK?  Let&#8217;s find out in this article.  As technology advances, we are more and more aware of the importance of network security.  The danger of cybercrime also increases year by year.  To deal with this, cybersecurity professionals are embarking on the development of new security tools to fight hackers every day.  Among these tools, there is a very famous framework called MITER ATTCK which contains different techniques, vulnerabilities and attack procedures for organizations to identify vulnerabilities in their systems.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet </span> ???? <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  ????</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><img post-id="12858" fifu-featured="1" decoding="async" class="aligncenter wp-image-47036 size-full" src="https://anonyviet.com/wp-content/uploads/2023/05/anonyviet4.jpg" alt="How to scan for system vulnerabilities with MITER ATTCK" title="How to scan for system vulnerabilities with MITER ATTCK" width="675" height="450" srcset="https://anonyviet.com/wp-content/uploads/2023/05/anonyviet4.jpg 675w, https://anonyviet.com/wp-content/uploads/2023/05/anonyviet4-300x200.jpg 300w" sizes="(max-width: 675px) 100vw, 675px" title="How to scan system vulnerabilities with MITER ATTCK 9"/></p>
<h2 id="ftoc-mitre-attck-la-gi" class="ftwp-heading">What is MITER ATT&#038;CK?</h2>
<p>MITER ATTCK (<a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fattack.mitre.org%2F%3Fref%3Dhackernoon.com" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">MITER AT&#038;CK</a>) is an open framework that contains real-world attack tactics and techniques.  This framework is completely free, it provides various tools for data protection or system security.</p>
<p>This framework allows us to share a common set of communication principles with other cybersecurity teams including: <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fred-team-va-blue-team-trong-an-ninh-mang-la-gi%2F" class="local-link" rel="noopener">red team</a>, blue team, SecOps, etc. In addition, it also mimics the behavior and tactics of attackers to help us identify risks and prepare defenses against possible attacks.  So it&#8217;s a great resource for IT security teams.</p>
<p>While it offers a lot of benefits, it&#8217;s still a tool, so it&#8217;s not perfect.  MITER AT&#038;CK has some limitations because not all techniques are malicious, so it can detect some that are not a real risk.</p>
<p>However, its advantages outweigh its disadvantages.  So I think you should try it, maybe it will be useful for your system.</p>
<p><img decoding="async" loading="lazy" class="size-full aligncenter" src="https://www.trellix.com/en-us/img/security-awareness/mitre-attack-enterprise.png" width="1875" height="1029" alt="How to scan system vulnerabilities with MITER ATTCK 6" title="How to scan system vulnerabilities with MITER ATTCK 10"/></p>
<h2 id="ftoc-cach-su-dung-mitre-attck" class="ftwp-heading">How to use MITER ATTCK</h2>
<p>In fact, this framework only describes and classifies malicious behavior, so we need a tool to apply all the information it provides.</p>
<p>You can implement it by mapping or continuous integration (CI/CD) using various cybersecurity tools.  The most common method is to use tools such as Security Information and Event Management (<a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.ibm.com%2Ftopics%2Fsiem%3Fref%3Dhackernoon.com" rel="noopener noreferrer ugc external nofollow" class="ext-link" onclick="this.target='_blank';">SIEM</a>) or Cloud Access Security Broker (<a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fbusiness%2Fsecurity-101%2Fwhat-is-a-cloud-access-security-broker-casb%3Fref%3Dhackernoon.com" rel="noopener noreferrer ugc external nofollow" class="ext-link" onclick="this.target='_blank';">CASB</a>).</p>
<p>Alternatively, you can deploy it in your CI/CD environment using tools like GitLab or Jenkins.</p>
<h2 id="ftoc-su-dung-mitre-attck-voi-kubescape-cloud" class="ftwp-heading">Using MITER ATTCK with Kubescape Cloud</h2>
<p>There are many different tools to scan and secure the system with MITER ATTCK.  But in this article, I will use the open source tool <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fgithub.com%2Fkubescape%2Fkubescape%3Fref%3Dhackernoon.com" rel="noopener noreferrer ugc external nofollow" class="ext-link" onclick="this.target='_blank';">Kubescape.</a></p>
<p>Kubescape is an open source tool for vulnerability scanning on K8s assemblies and YAML files, it checks for software vulnerabilities using RBAC and risk analysis, and detects misconfigurations according to various Frameworks, including the MITER ATTCK Framework.</p>
<h3 id="ftoc-demo-don-gian-su-dung-linux" class="ftwp-heading">Simple Demo Using Linux</h3>
<p>I just demo simply because according to the needs of each person, the process will be quite different.  You only need 3 steps to use Kubescape.</p>
<p><strong>Step 1:</strong> Download Kubescape.</p>
<p>I will download Kubescape to the device with Kubectl.  So you need to install <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fkubernetes.io%2Fdocs%2Ftasks%2Ftools%2Finstall-kubectl-windows%2F%3Fref%3Dhackernoon.com" rel="noopener noreferrer ugc external nofollow" class="ext-link" onclick="this.target='_blank';">Kubectl</a> and have the cluster running.  Then you just need to open terminal and run the command below:</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">url -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bash</pre>
<p><img decoding="async" loading="lazy" class="size-full wp-image-47056 aligncenter" src="https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-47.jpg" alt="How to scan system vulnerabilities with MITER ATTCK 7" width="773" height="173" srcset="https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-47.jpg 773w, https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-47-300x67.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-47-768x172.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-47-750x168.jpg 750w" sizes="auto, (max-width: 773px) 100vw, 773px" title="How to scan system vulnerabilities with MITER ATTCK 11"/></p>
<p><strong>Step 2:</strong> Run kubescape.  After successfully installing Kubescape, you can scan your system with the command below:</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">kubescape scan --submit</pre>
<p><img decoding="async" loading="lazy" class="size-full wp-image-47058 aligncenter" src="https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-48-1.jpg" alt="How to scan system vulnerabilities with MITER ATTCK 8" width="611" height="403" srcset="https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-48-1.jpg 611w, https://anonyviet.com/wp-content/uploads/2023/05/2023-05-09_11-48-1-300x198.jpg 300w" sizes="auto, (max-width: 611px) 100vw, 611px" title="How to scan system vulnerabilities with MITER ATTCK 12"/></p>
<p>As you can see, the cluster that I created is quite risky.  In addition, you can also export the scan results to PDF format.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;47035&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 0\/5 - (0 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;C\u00e1ch qu\u00e9t l\u1ed7 h\u1ed5ng h\u1ec7 th\u1ed1ng b\u1eb1ng MITRE ATTCK&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>
            <span class="kksr-muted">Rate this post</span>
    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-scan-for-system-vulnerabilities-with-miter-attck/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2023/05/anonyviet4.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to scan for XSS vulnerabilities automatically with Dalfox</title>
		<link>https://en.anonyviet.com/how-to-scan-for-xss-vulnerabilities-automatically-with-dalfox/</link>
					<comments>https://en.anonyviet.com/how-to-scan-for-xss-vulnerabilities-automatically-with-dalfox/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 15 Feb 2023 07:21:26 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Automatically]]></category>
		<category><![CDATA[Dalfox]]></category>
		<category><![CDATA[Scan]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[XSS]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=10018</guid>

					<description><![CDATA[Hello friends, in today&#8217;s article, I will show you how to use Dalfox tool to scan XSS vulnerabilities, this is a pretty cool and interesting tool, very useful for Pentester enthusiasts as well as Pentester enthusiasts. other Pentesters also like to use Dalfox. Before entering the article, I will briefly introduce the Dalfox tool and [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p><strong>Hello friends, in today&#8217;s article, I will show you how to use Dalfox tool to scan XSS vulnerabilities, this is a pretty cool and interesting tool, very useful for Pentester enthusiasts as well as Pentester enthusiasts. other Pentesters also like to use Dalfox.  Before entering the article, I will briefly introduce the Dalfox tool and the concept of XSS vulnerability.  Let&#8217;s get to the main point!</strong></p>
<p><span style="color: #ff0000;font-size: 12pt"><strong>Note: This article is for educational and research purposes only.  Please do not make illegal attacks.  Anonyviet will not be responsible for any and all illegal acts caused by you!</strong></span></p>
<h2><span style="color: #0000ff"><strong><span style="font-size: 18pt">Brief concept of XSS</span></strong></span></h2>
<p>Cross-Site Scripting (XSS) is a type of security attack where an attacker can insert malicious code into someone&#8217;s website and when the user visits that website, the malicious code will be executed on the other person&#8217;s machine. use that.  XSS can lead to loss of credit, disclosure of private information, or attack on user machines.</p>
<p>Here&#8217;s how it works: The XSS vulnerability works by injecting malicious code into a web page or a web page input form.  When a user visits a website or enters data into that form, malicious code will be executed on the user&#8217;s browser.  Malicious code can get information from the user&#8217;s browser, send it to another server, or perform other tasks such as attacking the user&#8217;s machine or losing credit.</p>
<h2><span style="color: #0000ff"><strong><span style="font-size: 18pt">Dalfox – Pentest Web Application Tool</span></strong></span></h2>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fgithub.com%2Fhahwul%2Fdalfox" rel="noopener">DalFox</a> is a powerful open source XSS scanner, parametric analyzer and utility that accelerates the detection and verification of XSS errors.  It comes with a powerful, feature-rich testing tool suitable for Pentester houses.  The author of this tool is <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fgithub.com%2Fhahwul" rel="noopener">HAHWUL</a>, is an engineer and a security researcher.  In addition, Dalfox is also one of the most useful web application pentest tools available today and should be used by every pentester to find and fix security holes in the website.</p>
<h2><span style="color: #0000ff"><strong><span style="font-size: 18pt">How to install Dalfox tool</span></strong></span></h2>
<p>To use Dalfox, of course you need to install it :>, and installing Dalfox is also quite simple, you just need to do the following:</p>
<p><strong>For Kali Linux</strong>: you just need to copy the Python code below, then save it with any name and the extension .py, here I save it as name.py, after pasting the code and saving the code, now you just need run the following command <code>sudo apt install golang -y</code> then run the Python script using the command <code>python tênfile.py</code></p>
<p>And so, Dalfox will automatically install on your Kali Linux machine</p>
<pre class="EnlighterJSRAW" data-enlighter-language="python">#!/usr/bin/env python3

import os
import sys

def install_golang_module(module):
    modulename = module.split("/")[-1].lower()
    if not os.path.exists("/opt/" + modulename):
        print("Installing go module " + modulename)
        cmdseries = ["sudo -E GO111MODULE=on go get -v " + module,
                     "sudo ln -s /opt/" + modulename + "/bin/" + \
                     modulename + " /usr/local/bin/" + modulename]
        os.environ["GOPATH"] = "/opt/" + modulename
        for cmdstring in cmdseries:
            os.system(cmdstring)

if __name__ == '__main__':
    golang_modules_to_install = ['github.com/hahwul/dalfox']
    for module in golang_modules_to_install:
        install_golang_module(module)

</pre>
<p><strong>For Windows</strong>: You just need to enter <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fgithub.com%2Fhahwul%2Fdalfox%2Freleases%2F" rel="noopener">This link</a>download and extract it then just open the terminal and run it</p>
<h2><span style="font-size: 18pt;color: #0000ff"><strong>How to use Dalfox?</strong></span></h2>
<p>To scan for XSS vulnerabilities on any website, we have the following command syntax:</p>
<p><code>dalfox url websitecoxss -b hawhul.xss.ht</code></p>
<p>For example:</p>
<p><code>dalfox url http://testphp.vulnweb.com:80/hpp/index.php?pp=FUZZ -b hawhul.xss.ht</code></p>
<p>And this is the result:</p>
<p><img post-id="10018" fifu-featured="1" decoding="async" loading="lazy" class="aligncenter wp-image-45053 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1.png" alt="How to scan for XSS vulnerabilities automatically with Dalfox" title="How to scan for XSS vulnerabilities automatically with Dalfox" width="1365" height="655" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1.png 1365w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1-300x144.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1-1024x491.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1-768x369.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1-750x360.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1-1140x547.png 1140w" title="How to scan for XSS vulnerabilities automatically with Dalfox 6"></p>
<p>In addition, Dalfox has a lot of different and interesting commands, you can find out for yourself at the page <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fgithub.com%2Fhahwul%2Fdalfox%2F" rel="noopener">GitHub</a> by Dalfox</p>
<h2><span style="font-size: 18pt;color: #0000ff"><strong>How to use Dalfox + ParamSpider for automatic vulnerability scanning</strong></span></h2>
<p>For those of you who do not know about the ParamSpider tool, the tool <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fgithub.com%2Fdevanshbatham%2FParamSpider" rel="noopener">Paramspider</a> developed by <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fgithub.com%2Fdevanshbatham" rel="noopener">Devansh Batham</a>, this tool has the function of “parametric mining from the dark corners of the web”.  Roughly speaking, it&#8217;s like Crawling potentially hacked urls.</p>
<p><strong>How to install Paramspider</strong>:</p>
<p><code>git clone https://github.com/devanshbatham/ParamSpider.git</code></p>
<p><code>cd ParamSpider</code></p>
<p><code>pip install -r requirements.txt</code>  or <code>pip3 install -r requirements.txt</code></p>
<p><code>python paramspider.py -d têndomain</code>  or <code> python3 paramspider.py -d têndomain</code></p>
<p><strong>How to take Paramspider + Dalfox</strong>:</p>
<p>Command syntax <code>python paramspider.py -d têndomain -o TênFileoutput.txt</code></p>
<p>For example:</p>
<p><code>python paramspider.py -d testphp.vulnweb.com -o vuln.xss</code></p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45054 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-7.png" alt="XSS SCAN" width="1365" height="693" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-7.png 1365w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-7-300x152.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-7-1024x520.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-7-768x390.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-7-750x381.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-7-1140x579.png 1140w" title="How to scan for XSS vulnerabilities automatically with Dalfox 7"></p>
<p>Output has the following form:</p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45055 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-8.png" alt="How to scan for XSS vulnerabilities automatically with Dalfox 3" width="1366" height="663" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-8.png 1366w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-8-300x146.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-8-1024x497.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-8-768x373.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-8-750x364.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-8-1140x553.png 1140w" title="How to scan for XSS vulnerabilities automatically with Dalfox 8"></p>
<p>Thus, we have the web urls, now switch to Dalfox to scan each url</p>
<p>The command syntax is as follows: <code>dalfox file đườngdẫnchứa\TênFileoutput.txt -b hawhul.xss.ht</code></p>
<p>For example: <code>dalfox file vuln.xss -b hawhul.xss.ht</code></p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45056 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-12.png" alt="scan xss website Dalfox" width="1360" height="698" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-12.png 1360w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-12-300x154.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-12-1024x526.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-12-768x394.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-12-750x385.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-12-1140x585.png 1140w" title="How to scan for XSS vulnerabilities automatically with Dalfox 9"></p>
<p>Here are the results that many of you expect:></p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45057 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-13.png" alt="How to scan for XSS vulnerabilities automatically with Dalfox 4" width="1365" height="698" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-13.png 1365w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-13-300x153.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-13-1024x524.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-13-768x393.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-13-750x384.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-13-1140x583.png 1140w" title="How to scan for XSS vulnerabilities automatically with Dalfox 10"></p>
<p>So there are quite a lot of Payload Xss shown !!!</p>
<p><strong>This article is the end, I hope you learn something from this article, if you encounter any website with XSS vulnerabilities, please report it to the web admin right away, maybe you can get money back, right?  :))</strong></p>
<p><strong>Wishing you all a very nice day!</strong></p>
<p><em><strong>You can also read more articles <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F10-website-giup-ban-thuc-hanh-ky-nang-hack-xss%2F" rel="noopener">10 websites to help you practice XSS hacking skills </a></strong></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-scan-for-xss-vulnerabilities-automatically-with-dalfox/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-15-1.png" medium="image"></media:content>
            	</item>
		<item>
		<title>Instructions for exploiting Sekat CMS vulnerabilities</title>
		<link>https://en.anonyviet.com/instructions-for-exploiting-sekat-cms-vulnerabilities/</link>
					<comments>https://en.anonyviet.com/instructions-for-exploiting-sekat-cms-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Mon, 30 Jan 2023 08:04:33 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cms]]></category>
		<category><![CDATA[exploiting]]></category>
		<category><![CDATA[Instructions]]></category>
		<category><![CDATA[Sekat]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=6674</guid>

					<description><![CDATA[Sekat CMS is currently suffering from a SQL Injection vulnerability, with only a few tips small, you can access the Admin admin rights of the Website, without having to spend a lot of time to exploit. Join the channel Telegram of the AnonyViet 👉 Link 👈 I&#8217;ll go straight to the point Step 1: Find [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div>
<p><strong>Sekat CMS is currently suffering from a SQL Injection vulnerability, with only a few <span style="color: #000000;"><a target="_blank" style="color: #000000;" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com" rel="noopener" class="local-link">tips</a></span>  small, you can access the Admin admin rights of the Website, without having to spend a lot of time to exploit.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>I&#8217;ll go straight to the point</p>
<p><span style="color: #008080; font-size: 14pt;"><strong>Step 1:</strong></span>  Find the <span style="color: #008000;">Website </span>use <span style="color: #33cccc;">Sket CMS</span> by Google</p>
<p>Enter the search command below into Google Search</p>
<pre class="lang:default decode:true">intext:"Developed by Sekat Technologies" -site:https://cxsecurity.com&#13;
</pre>
</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2017%2F03%2F1-1.jpg" rel="noopener" class="local-link"><img decoding="async" class="td-modal-image wp-image-4841  aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/03/1-1.jpg" alt="Instructions for exploiting the vulnerability of Sekat CMS 8" width="414" height="182" srcset="https://anonyviet.com/wp-content/uploads/2017/03/1-1.jpg 859w, https://anonyviet.com/wp-content/uploads/2017/03/1-1-300x132.jpg 300w, https://anonyviet.com/wp-content/uploads/2017/03/1-1-768x338.jpg 768w, https://anonyviet.com/wp-content/uploads/2017/03/1-1-750x330.jpg 750w" sizes="(max-width: 414px) 100vw, 414px" title="Instructions for exploiting the vulnerability of Sekat CMS 9"/></a></p>
<p><span style="font-size: 14pt;"><strong><span style="color: #008080;">Step 2:</span></strong></span>  Choose any 1 <span style="color: #008000;">Website</span> listed in Google</p>
<p>I will choose the page: <span style="color: #0000ff;">http://unstccs.com</span> to Test</p>
<p><span style="color: #008080; font-size: 14pt;"><strong>Step 3:</strong></span>  Access the Weblogin Admin using the link below</p>
<p><span class="td_text_highlight_marker_blue td_text_highlight_marker" style="color: #3366ff;">http://namewebiste.com<span style="color: #ffff00;">/member_login.php</span></span></p>
<p><span style="color: #800080;">Specifically would be:</span></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2017%2F03%2F2-1.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="alignnone wp-image-4842 size-full" src="https://anonyviet.com/wp-content/uploads/2017/03/2-1.jpg" alt="Instructions for exploiting the vulnerability of Sekat CMS 9" width="829" height="34" srcset="https://anonyviet.com/wp-content/uploads/2017/03/2-1.jpg 829w, https://anonyviet.com/wp-content/uploads/2017/03/2-1-300x12.jpg 300w, https://anonyviet.com/wp-content/uploads/2017/03/2-1-768x31.jpg 768w, https://anonyviet.com/wp-content/uploads/2017/03/2-1-750x31.jpg 750w" sizes="auto, (max-width: 829px) 100vw, 829px" title="Instructions for exploiting the vulnerability of Sekat CMS 10"/></a></p>
<p><span style="color: #008080; font-size: 14pt;"><strong>Step 4: </strong></span><span style="color: #000000;"><a target="_blank" style="color: #000000;" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com" rel="noopener" class="local-link">Exploit bugs</a> sign in</span>p equals fill <span style="color: #800080;">User</span> and <span style="color: #0000ff;">Pass</span> as below:</p>
<pre class="lang:default decode:true">Username: '=' 'or'&#13;
Password: '=' 'or'</pre>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2017%2F03%2F3-1.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class=" wp-image-4843 aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/03/3-1.jpg" alt="Instructions for exploiting the vulnerability of Sekat CMS 10" width="269" height="209" srcset="https://anonyviet.com/wp-content/uploads/2017/03/3-1.jpg 369w, https://anonyviet.com/wp-content/uploads/2017/03/3-1-300x234.jpg 300w" sizes="auto, (max-width: 269px) 100vw, 269px" title="Instructions for exploiting the vulnerability of Sekat CMS 11"/></a></p>
<p><strong><span style="color: #008080; font-size: 14pt;">Step 5:</span></strong>  Access to Admin rights, the next thing is yours</p>
<p>Should only be used for learning, do not destroy others</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2017%2F03%2F4-1.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="wp-image-4844 aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/03/4-1.jpg" alt="Instructions for exploiting the vulnerability of Sekat CMS 11" width="532" height="354" srcset="https://anonyviet.com/wp-content/uploads/2017/03/4-1.jpg 1426w, https://anonyviet.com/wp-content/uploads/2017/03/4-1-300x200.jpg 300w, https://anonyviet.com/wp-content/uploads/2017/03/4-1-1024x681.jpg 1024w, https://anonyviet.com/wp-content/uploads/2017/03/4-1-768x511.jpg 768w, https://anonyviet.com/wp-content/uploads/2017/03/4-1-750x499.jpg 750w, https://anonyviet.com/wp-content/uploads/2017/03/4-1-1140x759.jpg 1140w" sizes="auto, (max-width: 532px) 100vw, 532px" title="Instructions for exploiting the vulnerability of Sekat CMS 12"/></a></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;4839&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
<p><!-- AI CONTENT END 2 --></p></div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/instructions-for-exploiting-sekat-cms-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2017/03/5-1.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Scan any website for vulnerabilities with Nikto</title>
		<link>https://en.anonyviet.com/scan-any-website-for-vulnerabilities-with-nikto/</link>
					<comments>https://en.anonyviet.com/scan-any-website-for-vulnerabilities-with-nikto/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sun, 29 Jan 2023 13:41:45 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Nikto]]></category>
		<category><![CDATA[Scan]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Website]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=6210</guid>

					<description><![CDATA[Scan any website for vulnerabilities with Nikto Join the channel Telegram of the AnonyViet 👉 Link 👈 Website is an extremely large and vast information network. But there&#8217;s also no guarantee that websites are free of vulnerabilities. The vulnerability allows unauthorized access and unreasonable exploitation by others. Easily affect the website&#8217;s database. Current hackers prefer [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p style="text-align: center;"><span style="font-size: 18pt; color: #4285f4;">Scan any website for vulnerabilities with Nikto</span></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>Website is an extremely large and vast information network.  But there&#8217;s also no guarantee that websites are free of vulnerabilities.  The vulnerability allows unauthorized access and unreasonable exploitation by others.</p>
<p>Easily affect the website&#8217;s database.  Current hackers prefer to hack the web rather than hack apps or hardware.  This paragraph <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com" rel="noopener" class="local-link">AnonyViet</a> Please allow me to talk about the vulnerability scanning tool that is taking Nikto by storm.</p>
<h2 id="ftoc-cong-cu-quet-lo-hong-bao-mat-nikto" class="ftwp-heading"><span style="font-size: 14pt; color: #4285f4;">Nikto Vulnerability Scan Tool?</span></h2>
<p>The Nikto tool was born, but not on anyone&#8217;s side.  Hackers can use it to scan for vulnerabilities and gain unauthorized access.  But programmers can also use it to scan for vulnerabilities.  Then, patch the vulnerability before the website is attacked by bad guys.  That&#8217;s why I said Nikto isn&#8217;t on anyone&#8217;s side.  It will be good or bad depending on the purpose of the user.</p>
<p>Nikto will check the overall website then report the detected vulnerabilities.</p>
<p>Cons: Although Nikto scans for vulnerabilities extremely quickly and efficiently.  But it&#8217;s not sneaky.  Any website with IDS or anti-phishing measures.  Then it will immediately detect you are scanning it and send a notification to the admin.</p>
<h2 id="ftoc-thu-nghiem-quet-bao-mat-bang-nikto" class="ftwp-heading"><span style="font-size: 14pt; color: #4285f4;">Testing security scanning with Nikto</span></h2>
<p>On a computer running kali linux or other distribution versions of Kali.</p>
<p>Please visit in order <span style="color: #34a853;"><strong>Kali Linux</strong> -> <strong>Vulnerability Analysis</strong> -> <strong>Misc Scanners</strong> -> <strong>nikto</strong><strong>. </strong></span></p>
<p><img decoding="async" class="lightbox aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/11/lo-hong-bao-mat-1.jpg" alt="Scan any website for vulnerabilities with Nikto" width="640" height="463" data-i="0" title="Guide to Hack Website with Nitko on Kali Linux 12"/></p>
<p>Nikto gives us a lot of options.  But here we will use a simple and basic syntax as follows:</p>
<p style="text-align: center;"><span style="color: #ea4335; font-size: 12pt;"><em>nikto -h <IP or hostname></em></span></p>
<h3 id="ftoc-tiep-theo-cac-ban-tien-hanh-quet-may-chu-web-web-server" class="ftwp-heading"><span style="font-size: 14pt; color: #4285f4;">Next, you proceed to scan the Web server (Web Server).</span></h3>
<p>We will test on a secure Websever server.  The example below is the http protocol.</p>
<p>To conduct a vulnerability scan, type the following command:</p>
<p style="text-align: center;"><span style="color: #ea4335; font-size: 12pt;"><em>nikto -h 192.168.1.104</em></span></p>
<p>After typing the scan command, Nikto will give a series of information as shown below.</p>
<p><img decoding="async" loading="lazy" class="lightbox aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/11/lo-hong-bao-mat-2.jpg" alt="Scan any website for vulnerabilities with Nikto" width="640" height="431" data-i="1" title="Guide to Hack Website with Nitko on Kali Linux 13"/></p>
<p style="text-align: center;"><span style="font-size: 12pt; color: #ea4335;">The information that Nikto shows us includes</span></p>
<p>The server is <span style="color: #34a853;">Apache 2.2.14</span>possibly running under Ubuntu.</p>
<p>It also lists more information about possible security holes at the bottom.  This is important information for users to check the website again.</p>
<p>Please notice at the bottom of the page there are words about OSVDB.  This is open source website vulnerability data.  Because now and in the future, the website will use open source a lot, so please take note.</p>
<h3 id="ftoc-cuoi-cung-la-quet-trang-web" class="ftwp-heading"><span style="font-size: 14pt; color: #4285f4;">Finally, Web Scraping</span></h3>
<p>After scanning the server for vulnerabilities <span style="color: #34a853;">Webserver</span> above, we continue to scan the website.  This is also our main purpose in this article.</p>
<p>We are going to test a website.  Try with page <span style="color: #4285f4;">webscantest.com.</span></p>
<p style="text-align: center;">This is the command to use in this case.</p>
<p style="text-align: center;"><span style="color: #ea4335; font-size: 12pt;"><em>nikto -h webscantest.com</em></span></p>
<p><img decoding="async" loading="lazy" class="lightbox aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/11/lo-hong-bao-mat-3.jpg" alt="Scan any website for vulnerabilities with Nikto" width="640" height="431" data-i="2" title="Guide to Hack Website with Nitko on Kali Linux 14"/></p>
<p>Nikto has identified the Apache 2.2.14 Ubuntu server as I mentioned above.</p>
<p>It then scans for an overview of potential vulnerabilities found on this site.  Open source OSVDB vulnerabilities have been found.</p>
<p>Please visit the website <a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2FOsvdb.org" rel="noopener noreferrer external nofollow" class="ext-link" onclick="this.target='_blank';">Osvdb.org</a> to find more information for the specific OSVDB vulnerability in the image above.</p>
<p><img decoding="async" loading="lazy" class="lightbox aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/11/lo-hong-bao-mat-4.jpg" alt="Scan any website for vulnerabilities with Nikto" width="640" height="341" data-i="3" title="Guide to Hack Website with Nitko on Kali Linux 15"/></p>
<p>We will use this page to find information about one of the vulnerabilities identified by nikto like<span style="color: #4285f4;"> <strong>OSVDB-877</strong>.</span></p>
<p><img decoding="async" loading="lazy" class="lightbox aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/11/lo-hong-bao-mat-5.jpg" alt="Scan any website for vulnerabilities with Nikto" width="640" height="341" data-i="4" title="Guide to Hack Website with Nitko on Kali Linux 16"/></p>
<p>You can look down at the bottom of this page.  It will provide a number of other sources of information about the problem you are looking for.  Sources from<span style="color: #4285f4;"> Nikto, Nessus and Snort.</span></p>
<p><img decoding="async" loading="lazy" class="lightbox aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/11/lo-hong-bao-mat-6.jpg" alt="Vulnerability information and reference links" width="640" height="345" data-i="5" title="Guide to Hack Website with Nitko on Kali Linux 17"/></p>
</p>
<h3 id="ftoc-tiep-tuc-thu-nghiem-quet-facebook" class="ftwp-heading"><span style="font-size: 14pt; color: #4285f4;">Continue testing Facebook Scan</span></h3>
<p>Now we will experiment with the king of social networks.  Let&#8217;s see if this king has a hole or not.  Please continue to use the old command.</p>
<p style="text-align: center;"><span style="color: #ea4335; font-size: 12pt;"><em>nikto -h facebook.com</em></span></p>
<p><img decoding="async" loading="lazy" class="lightbox aligncenter" src="https://anonyviet.com/wp-content/uploads/2017/11/lo-hong-bao-mat-8.jpg" alt="Scan Facebook" width="640" height="432" data-i="7" title="Guide to Hack Website with Nitko on Kali Linux 18"/></p>
<p>You see it.  Facebook is extremely secure.  It even hides its server name because it has its own server.  Built specifically for Facebook for billions of dollars.  So Facebook does not disclose any information about its server at all.</p>
<p>The open source OSVDB vulnerability is also not found on this site.  It only scans robots.txt content hits.  And this is not worth mining, anyone who knows SEO website will know what robots.txt is.  Just to make it compatible with the google search engine only.</p>
<p>You can&#8217;t see any serious error messages on facebook.  There are only a few minor display errors.  So hacking Facebook is a very difficult thing, everyone.</p>
<p>Like <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com" rel="noopener" class="local-link">Fanpage</a> to update more good articles.</p>
<p style="text-align: right;"><span style="color: #ea4335;">Internet source</span><br /><span style="color: #ea4335;">Lmint.</span></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;7086&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/scan-any-website-for-vulnerabilities-with-nikto/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2017/11/need-a-help-4.png" medium="image"></media:content>
            	</item>
		<item>
		<title>What is SQL Injection?  How to Prevent SQL Injection Vulnerabilities</title>
		<link>https://en.anonyviet.com/what-is-sql-injection-how-to-prevent-sql-injection-vulnerabilities/</link>
					<comments>https://en.anonyviet.com/what-is-sql-injection-how-to-prevent-sql-injection-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sun, 29 Jan 2023 09:49:33 +0000</pubDate>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[prevent]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=6115</guid>

					<description><![CDATA[SQL injection vulnerabilities arise when you make unsafe database queries. Simply put, users can view your website&#8217;s database by entering a query into the URL or filling in the form. Don&#8217;t take SQL injection lightly because it&#8217;s in Top 10 web security vulnerabilities according to OWASP 2020 announcement there. Join the channel Telegram of the [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>SQL injection vulnerabilities arise when you make unsafe database queries.  Simply put, users can view your website&#8217;s database by entering a query into the URL or filling in the form.  Don&#8217;t take SQL injection lightly because it&#8217;s in <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftop-10-lo-hong-bao-mat-web-theo-cong-bo-owasp-2020%2F" rel="noopener" class="local-link">Top 10 web security vulnerabilities according to OWASP 2020 announcement</a> there.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2021%2F05%2Fsql-injection.jpg" rel="noopener" class="local-link"><img post-id="6115" fifu-featured="1" decoding="async" class="aligncenter size-full wp-image-26982" src="https://anonyviet.com/wp-content/uploads/2021/05/sql-injection.jpg" alt="What is SQL Injection?  How to Prevent SQL Injection Vulnerabilities" title="What is SQL Injection?  How to Prevent SQL Injection Vulnerabilities" width="838" height="439" srcset="https://anonyviet.com/wp-content/uploads/2021/05/sql-injection.jpg 838w, https://anonyviet.com/wp-content/uploads/2021/05/sql-injection-300x157.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/05/sql-injection-768x402.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/05/sql-injection-750x393.jpg 750w" sizes="(max-width: 838px) 100vw, 838px" title="What is SQL Injection?  How to Prevent SQL Injection Vulnerability 6"/></a></p>
<h2 id="ftoc-cach-khai-thac-lo-hong-sql-injection" class="ftwp-heading">How to exploit SQL Injection vulnerability</h2>
<p>The simplest is to use the SQLi auto exploit tool.  I usually use <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F%3Fs%3Dsqlmap" rel="noopener" class="local-link">SQLmap</a>, because according to experience this is the tool with the best possible exploitation.  But the downside is that you have to use commands instead of interfaces.</p>
<p>Or you can use the tool <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F%3Fs%3DSQL%2BDumper" rel="noopener" class="local-link">SQL Dumper</a> has an interface with more features that are easier to set up.  If you are new to learning, you can try this tool to exploit the Website&#8217;s database.</p>
<h2 id="ftoc-lam-the-nao-de-ngan-chan-lo-hong-sql-injection" class="ftwp-heading">How to prevent SQL injection vulnerabilities?</h2>
<p>The best way to prevent SQL injection vulnerabilities is to use a framework that allows you to securely filter input data before it enters the database.  ORM (Object Relational Mapper) is a good option that you should try.  For additional layers of security, validate all input and use WAF (Web Application Firewall).</p>
<h3 id="ftoc-vi-du-don-gian" class="ftwp-heading">Simple example</h3>
<p>Let&#8217;s say I have a Java application that allows users to retrieve their documents by ID.  I can do it like this:</p>
<pre><code>String query = "SELECT * FROM documents WHERE ownerId=" + authContext.getUserId() + " AND documentName="" + request.getParameter("docName") + """;&#13;
executeQuery(query);</code></pre>
<p>If the user ID is 25 and the URL is https://www.example.com/documents/?docName=ABC123, the query would be:</p>
<pre><code>SELECT * FROM documents WHERE ownerId=25 AND documentName="ABC123";</code></pre>
<p>Still fine, right?  But what if the URL is https://www.example.com/documents/?docName=ABC123&#8217;OR&#8217;1&#8217;=&#8217;1?</p>
<p>Now I will get the following query that returns all documents of all users (because 1 = 1 is always true):</p>
<pre><code>SELECT * FROM documents WHERE ownerId=25 AND documentName="ABC123" OR '1'='1';</code></pre>
<p>So how to avoid this error?</p>
<h2 id="ftoc-su-dung-object-relational-mapping" class="ftwp-heading">Using Object Relational Mapping</h2>
<p>Taking Java as an example, using an ORM such as hibernate to implement JPA (Java Persistence API) might look like this.</p>
<p>First, define the model.</p>
<pre><code>@Entity&#13;
public <span class="hljs-class">class Document </span>{&#13;
  @Id&#13;
  @GeneratedValue(strategy=GenerationType.AUTO)&#13;
  private Long id;&#13;
  private String documentName;&#13;
  private Integer ownerId;&#13;
}</code></pre>
<p>Then define the class repository.</p>
<pre><code>@Repository&#13;
public <span class="hljs-class">interface DocumentRepository extends JpaRepository&lt;Document, Long&gt; </span>{&#13;
  <span class="hljs-function">List&lt;Document&gt; findByDocumentNameAndOwnerId(String documentName, Integer ownerId)</span>;&#13;
}</code></pre>
<p>Finally, you can use the repository and fetch the documents as follows:</p>
<pre><code>List&lt;Document&gt; docs = documentRepository.findByDocumentNameAndOwnerId(request.getParameter("docName"), authContext.getUserId());</code></pre>
<p>The ORM will handle all parameters safely.  Now suppose you want more control over the queries.  In that case, many ORMs provide query builder you can use, such as the Hibernate Criteria API.</p>
<p>If you use Python, Django has an equally great ORM;  If you don&#8217;t use Django, sqlalchemy is a great option.</p>
<p>PHP has Doctrine.  You just need to google to search for ORMs that match the technology of your choice.</p>
<h3 id="ftoc-canh-bao" class="ftwp-heading">Warning</h3>
<div class="TnITTtw-original-wrap TnITTtw-padded-single-translation TnITTtw-t">
<p>ORM frameworks are not 100% perfect.</p>
<p>The first is that they still have the functionality to support raw SQL queries/query parts.  You just need to avoid using those features.</p>
<p>The second is that ORM frameworks often have security holes, just like any other software package.  So learn other good practices: validate all input data, use WAF, update packages…</p>
</div>
<div class="TnITTtw-padded-single-translation TnITTtw-trans-wrap TnITTtw-t">
<h2 id="ftoc-prepared-statements" class="ftwp-heading">Prepared statements</h2>
<p>Prepared statements are a more manual choice and should be avoided because compared to ORMs, it has a significantly higher risk of human error.  However, this still beats the simple string concatenation method (like the example above).  This approach looks like this:</p>
<div>
<pre><code>String query = "SELECT * FROM documents WHERE ownerId=? AND documentName = ?";&#13;
PreparedStatement ps = conn.prepareStatement(query);&#13;
ps.setString(1, authContext.getUserId());&#13;
ps.setString(2, request.getParameter("docName"));&#13;
ResultSet rs = ps.executeQuery();</code></pre>
<p>In theory, this is pretty safe.  However, in my experience, as the codebase grows larger, mistakes will start to appear.  You only need one mistake to be completely attacked.  Cases like arrays (documentId IN (“foo”, “bar”)) are where devs often make mistakes.</p>
<p>So if you decide to use this approach, be careful with it when you extend the codebase.</p>
<h2 id="ftoc-web-application-firewall" class="ftwp-heading">Web Application Firewall</h2>
<p>WAF products should not be considered a good SQL injection control.  But they are a great extra layer of security and are often quite effective against SQL injection attacks.</p>
<p>A great open source solution is to deploy Apache with ModSecurity CRS in front of your webapp.</p>
<h2 id="ftoc-database-firewall" class="ftwp-heading">Database Firewall</h2>
<p>Depending on your database and budget, you might consider trying out database firewalls.  I have never tried this, but you can also find out the link below, maybe it will help you.</p>
<h2 id="ftoc-ket-luan" class="ftwp-heading">Conclusion</h2>
<p>SQL injection is a simple injection vulnerability.  And like all security holes, you can prevent it by using an appropriate library or framework for building the protocol, in this case SQL.</p>
</div>
<p>ORM is safer than prepared statements.  And if you don&#8217;t need too much control over the queries, use a lower level ORM commonly known as a query builder.  WAF can add an extra layer of security, but you should never rely on it for security.</p>
</div>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;26928&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;101&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (101 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (101 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/what-is-sql-injection-how-to-prevent-sql-injection-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/05/sql-injection.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to use XSS-Freak to exploit XSS vulnerabilities automatically</title>
		<link>https://en.anonyviet.com/how-to-use-xss-freak-to-exploit-xss-vulnerabilities-automatically/</link>
					<comments>https://en.anonyviet.com/how-to-use-xss-freak-to-exploit-xss-vulnerabilities-automatically/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sat, 28 Jan 2023 00:36:11 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Automatically]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[XSSFreak]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=5268</guid>

					<description><![CDATA[XSS-Freak is a tool written entirely in Python3 to perform XSS vulnerability scanning on the network. This tool scans XSS to crawl the entire website and scans all possible directories and links to expand its attack range. It then activates the search to get information about the input tags. Next, it will start sending requests [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p>XSS-Freak is a tool written entirely in Python3 to perform XSS vulnerability scanning on the network.  This tool scans XSS to crawl the entire website and scans all possible directories and links to expand its attack range.  It then activates the search to get information about the input tags.  Next, it will start sending requests with XSS included.  If the site has an input that is vulnerable to exploitation and is not secure from XSS attacks, XSS-Freak will detect it within seconds.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2020%2F04%2Fxss-freak.jpg" rel="noopener" class="local-link"><img post-id="5268" fifu-featured="1" decoding="async" width="532" height="327" class="aligncenter size-full wp-image-18895" src="https://anonyviet.com/wp-content/uploads/2020/04/xss-freak.jpg" alt="How to use XSS-Freak to exploit XSS vulnerabilities automatically" title="How to use XSS-Freak to exploit XSS vulnerabilities automatically" srcset="https://anonyviet.com/wp-content/uploads/2020/04/xss-freak.jpg 532w, https://anonyviet.com/wp-content/uploads/2020/04/xss-freak-300x184.jpg 300w" sizes="(max-width: 532px) 100vw, 532px" title="How to use XSS-Freak to exploit automatic XSS vulnerability 7"/></a></p>
<h2 id="ftoc-vay-xss-la-gi" class="ftwp-heading">So what is XSS?</h2>
<p>XSS, also known as cross-site scripting, is known as a type of vulnerability found in web applications.  With the help of XSS, attackers can inject malicious scripts into (seemingly) trusted websites.</p>
<p>Cross-site Scripting (XSS) is one of the most popular hacking techniques when it comes to vulnerabilities on the web.  This error occurs when a website generates output based on user input.  If the website takes data from the input without proper validation and encryption, it will surely be exploited by hackers.</p>
<p>XSS allows hackers to run malicious JavaScript commands in the victim&#8217;s browser, which can take over <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Foptshare.com%2Fblog%2Fgiai-thich-mot-thuat-ngu-co-ban-trong-google-analytics%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">user session</a>. , nude photos, &#8230;.</p>
<p>Security flaws in web applications allow these attacks to happen very often.  These errors are quite common and occur in web applications that require user input.</p>
<p>To learn more about Cross-site Scripting (XSS) and its other types, see <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.cyberpunk.rs%2Fcross-site-scripting-xss-explanation-details" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Cross-site Scripting (XSS) detailed explanation</a>.</p>
<h2 id="ftoc-tinh-nang" class="ftwp-heading">Feature:</h2>
<p>– Send Payloads XSS</p>
<p>– Written entirely in python3</p>
<h2 id="ftoc-he-dieu-hanh-ho-tro" class="ftwp-heading">Supported operating systems:</h2>
<h2 id="ftoc-yeu-cau" class="ftwp-heading">Request:</h2>
<p>– High speed internet connection</p>
<p>– The PC is capable of processing a large number of data streams simultaneously</p>
<h2 id="ftoc-xss-freak-hoat-dong-nhu-the-nao" class="ftwp-heading">How does XSS-Freak work</h2>
<p>To perform an attack, a target (web victim) and a list of different XSS payloads are required.  The tool will now start scanning the main web pages including indexed pages for possible directories and links in the site.  It then scans all the folders found in the initial scan and puts them in attack range.  Furthermore, it will scan all the links found in both scans.</p>
<p>Then XSS-Freak will add all HTML input tags to the attack range.  It will start the attack on both HTML input tags using Payloads XSS.  If web input tags are not handled properly, the tool will detect those vulnerabilities right away.</p>
<h2 id="ftoc-uu-diem" class="ftwp-heading">Advantage:</h2>
<p>– Due to the use of multi-threading, processing is fast and efficient</p>
<p>– Capable of crawling complete webs</p>
<h2 id="ftoc-nhuoc-diem" class="ftwp-heading">Defect:</h2>
<p>– Not supported on phones</p>
<p>&#8211; Must have high speed Internet connection</p>
<p>– Requires good hardware</p>
<h2 id="ftoc-cai-dat-xss-freak" class="ftwp-heading">Install XSS-Freak</h2>
<p>You run the following commands:</p>
<p><code><span style="font-size: 12pt;">git clone https://github.com/sepulvedazallalinux/XSS-Freak.git </span></code></p>
<p><code><span style="font-size: 12pt;">cd XSS-Freak/</span></code></p>
<p><code/><code/><code/><code><span style="font-size: 12pt;">pip3 install -r requirements.txt</span></code></p>
<p><span style="font-size: 12pt;"><code>python3 XSS-Freak.py</code></span></p>
<h2 id="ftoc-cach-su-dung" class="ftwp-heading">Using</h2>
<p><img decoding="async" loading="lazy" width="651" height="437" class="size-full wp-image-18901 aligncenter" src="https://anonyviet.com/wp-content/uploads/2020/04/a.png" alt="How to use XSS-Freak to exploit automatic XSS vulnerability 3" srcset="https://anonyviet.com/wp-content/uploads/2020/04/a.png 651w, https://anonyviet.com/wp-content/uploads/2020/04/a-300x201.png 300w" sizes="auto, (max-width: 651px) 100vw, 651px" title="How to use XSS-Freak to exploit automatic XSS vulnerability 8"/></p>
<p>The first arrow is where you enter<a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Fwww.insecurelabs.org%2Ftask%2FRule1" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';"> web link</a> want to attack xss in.</p>
<p>The second arrow, you enter the file name containing <strong><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.fshare.vn%2Ffile%2FHPTOPAWIL5MG" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">payloads xss</a>.</strong> Note, this file must be in the same directory as the tool.</p>
<p>The processing depends on your CPU and network connection.</p>
<p>Good luck!</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;18882&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-use-xss-freak-to-exploit-xss-vulnerabilities-automatically/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2020/04/xss-freak.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Top 10 web security vulnerabilities according to OWASP 2020 announcement</title>
		<link>https://en.anonyviet.com/top-10-web-security-vulnerabilities-according-to-owasp-2020-announcement/</link>
					<comments>https://en.anonyviet.com/top-10-web-security-vulnerabilities-according-to-owasp-2020-announcement/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Fri, 27 Jan 2023 13:04:30 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[announcement]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Top]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[web]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=4889</guid>

					<description><![CDATA[OWASP stands for Open Web Application Security Project, an online community dedicated to producing articles, methods, documents, tools and technologies in the field of web application security. Every 3.4 years or annually OWASP publishes a list of common and dangerous vulnerabilities encountered. Here is a list of 10 vulnerabilities 2020 Join the channel Telegram of [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>OWASP stands for Open Web Application Security Project, an online community dedicated to producing articles, methods, documents, tools and technologies in the field of web application security.  Every 3.4 years or annually OWASP publishes a list of common and dangerous vulnerabilities encountered.  Here is a list of 10 vulnerabilities 2020</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><img post-id="4889" fifu-featured="1" decoding="async" class="aligncenter wp-image-22223 size-full" src="https://anonyviet.com/wp-content/uploads/2020/09/71.png" alt="Top 10 web security vulnerabilities according to OWASP 2020 announcement" title="Top 10 web security vulnerabilities according to OWASP 2020 announcement" width="480" height="320" srcset="https://anonyviet.com/wp-content/uploads/2020/09/71.png 480w, https://anonyviet.com/wp-content/uploads/2020/09/71-300x200.png 300w" sizes="(max-width: 480px) 100vw, 480px" title="Top 10 web security vulnerabilities according to OWASP 2020 announcement 6"/></p>
<h2 id="ftoc-top-10-owasp-la-gi" class="ftwp-heading">What is the OWASP Top 10?</h2>
<p>The OWASP Top 10 is a list of the 10 most common web vulnerabilities.  It also shows the risks, impacts and countermeasures of these vulnerabilities.  Updated every three to four years, <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fowasp.org%2Fwww-project-top-ten%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Latest OWASP vulnerability list released in 2018</a>.</p>
<h2 id="ftoc-top-10-lo-hong-hang-dau-cua-owasp-vao-nam-2020" class="ftwp-heading">OWASP Top 10 Vulnerabilities in 2020</h2>
<h3 id="ftoc-injection" class="ftwp-heading">Injection</h3>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fcategory%2Fsecurity%2Fsql-injection%2F" rel="noopener noreferrer" class="local-link">Injection</a> allowing attackers to pump malicious code through one application to another.  These attacks exploit the operating system through system calls, the use of external programs via shell commands, as well as calls to the sub-database via SQL (i.e. SQL Injection). ).  Entire scripts can be written in Perl, Python, and other languages ​​that attack poorly designed applications.  Anytime an application uses an interpreter of any kind there is a risk of creating a security hole.  Injection was ranked 1st in OWASP in 2018.</p>
<h3 id="596d" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Broken Authentication</h3>
<p>Broken authentication is a protective term for a number of vulnerabilities that attackers exploit to impersonate users to blatantly gain access to the system.  It is roughly understood as impersonating the user&#8217;s identity.  In general, broken authentication refers to weaknesses in two areas: session management and credential management.  Both are classified as broken authentication because attackers use one of two ways to impersonate users: compromised session IDs or stolen credentials.</p>
<p>Attackers use a variety of strategies to take advantage of these weaknesses, ranging from massive credential stuffing attacks to highly targeted conspiracies to gain access to sensitive information. login credentials of a specific person.</p>
<h3 id="d30f" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Sensitive Data Exposure</h3>
<p>Sensitive Data Exposure occurs when an application, company or organization inadvertently exposes personal data.  SDE (Sensitive Data Exposure) is different from a data breach, in that an attacker will access and steal your information.</p>
<p>The loss of sensitive data occurs due to inadequate protection of the database where the information is stored.  This can be the result of many reasons such as weak coding, no encryption, software bugs, or when someone mistakenly uploads data to the wrong database.</p>
<p>Different types of data may be displayed in some sensitive data.  Bank account number, credit card number, healthcare data, session key, home address, phone number, date of birth and user account information such as username and password are one number of types of information that may be exposed.  Although the disclosure is by the user, it is still on the OWASP list.</p>
<h3 id="c361" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">XML External Entities (XXE)</h3>
<p>XML External Entities (also known as XXE) is a security vulnerability that allows an attacker to interfere with an application&#8217;s processing of XML data.  It typically allows an attacker to view files on the application server&#8217;s file system and interact with any third-party back-end or external systems that the application can access.</p>
<p>In some situations, an attacker can escalate a XXE attack to compromise the underlying server or other backend infrastructure, by taking advantage of the XXE vulnerability to perform request spoofing attacks. server-side request (SSRF).</p>
<h3 id="4b28" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Broken Access control</h3>
<p>Access control enforces the policy so that users cannot act outside of their authority.  Errors often lead to unauthorized disclosure of information, modification or destruction of all data, or performance of features beyond the user&#8217;s limits.  Common access control vulnerabilities include:</p>
<ul>
<li>Bypass checks access by modifying URLs, internal application state, or HTML pages, or simply using a custom API hack.</li>
<li>Allows to change the primary key to another user&#8217;s record, allows viewing or editing of other people&#8217;s accounts.</li>
<li>Enhanced privileges.  Act as a user without logging in or act as an administrator when logged in as a user.</li>
<li>Manipulating metadata, such as replaying or forging a JSON Web Token (JWT) access control token, or hidden cookies or fields, manipulated to elevate privileges or to abuse JWT disabling.</li>
<li>CORS misconfiguration allows unauthorized API access.</li>
<li>Force browsing to pages authenticated as user or to privileged pages as standard user.  API access with missing access controls for POST, PUT, and DELETE.</li>
</ul>
<h3 id="ftoc-cau-hinh-bao-mat-sai" class="ftwp-heading">Wrong security configuration</h3>
<p>The following security configurations are improperly or unsafely configured security settings that put your system and data at risk.  Essentially, any well-documented configuration changes, default settings, or technical problems on any component of your endpoint lead to misconfiguration.</p>
<p>Misconfiguration can happen due to a multitude of reasons.  Modern network infrastructures are so complex that organizations often overlook important security settings, including new network equipment that is still configured by default.  A developer can write flexible firewall rules and create network shares for his convenience while building software.  Sometimes administrators allow configuration changes for testing or troubleshooting purposes and forget to return the original state resulting in misconfiguration.  Some common security misconfiguration vulnerabilities are login security, user account management, password policy, and legacy protocols.</p>
<h3 id="ftoc-cross-site-scripting-xss" class="ftwp-heading">Cross Site Scripting (XSS)</h3>
<p>Cross-site Scripting (XSS) is a client-side code injection attack.  The attacker aims to execute malicious scripts in the victim&#8217;s web browser by injecting malicious code into a legitimate website or web application.  The actual attack occurs when the victim visits a website or web application that executes malicious code.  The website or web application becomes a vehicle for delivering malicious scripts to the user&#8217;s browser.  Commonly used vulnerable targets for Cross-site Scripting attacks are forums, message boards, and comment-enabled websites.</p>
<p>A website or web application is vulnerable to XSS attacks if it uses unfiltered user input.  User input must be parsed by the browser.  XSS attacks can happen in VBScript, ActiveX, Flash, and even CSS.  However, they are most common in JavaScript, mainly because JavaScript is the foundation for most browsing experiences.  Almost everyone who learns about OWASP knows about this vulnerability.</p>
<h3 id="7e4f" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Insecure Deserialization</h3>
<p><strong>Deserialization</strong> is the process of restoring this stream of bytes into a fully functional copy of the original object, in the exact state when it was serialized.  The web logic can then interact with this object, just like any other object.</p>
<p><strong class="hi ir">Serialization (serialization)</strong> is the process of converting complex data structures, such as objects and their fields, into a &#8220;flatter&#8221; format that can be sent and received as a sequential stream of bytes.  The ordering of data lies in the purpose of:</p>
<ul>
<li>Write complex data to inter-process memory, files, or databases.</li>
<li>Send complex data, such as over a network, between different components of an application or within an API call.</li>
</ul>
<p>Importantly, when serializing an object, its state is also maintained.  In other words, the properties of the object are preserved, along with their specified values.</p>
<h3 id="ftoc-su-dung-cac-thanh-phan-co-lo-hong-da-biet" class="ftwp-heading">Using components with known vulnerabilities</h3>
<p>Known vulnerabilities are those that have been discovered in open source components and published in the NVD, security advisor, or issue tracker.  As of the time of publication, a security hole can be exploited by hackers who find documentation related to them.  According to OWASP, the problem of using vulnerable components is very common.  Furthermore, the use of open source components is so widespread that many development leaders don&#8217;t even know what they&#8217;ve accomplished.</p>
<h3 id="ftoc-ghi-nhat-ky-va-giam-sat-khong-day-du" class="ftwp-heading">Inadequate logging and monitoring</h3>
<p>When an organization does not have sufficient logging, detection, monitoring and response capabilities, attackers will rely on these weaknesses to achieve their goals undetected.  The lack of these methods includes things like:</p>
<ul>
<li>Auditable events, such as logins, failed logins, and high value transactions are not logged.</li>
<li>Warnings and errors produce incomplete or ambiguous log messages.</li>
<li>Logs of unmonitored applications and APIs for suspicious activity.</li>
<li>Logs are stored locally only.</li>
<li>Appropriate alarm thresholds and out-of-place or ineffective feedback reporting procedures.</li>
<li>Penetration testing and scanning with DAST tools did not trigger warnings.</li>
<li>Applications cannot detect, report, or warn about active attacks in real time or near real time.</li>
</ul>
<p>Above is a list of Top 10 OWASP Vulnerabilities in 2020.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;22221&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/top-10-web-security-vulnerabilities-according-to-owasp-2020-announcement/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2020/09/71.png" medium="image"></media:content>
            	</item>
	</channel>
</rss>
